Remote Code Execution Vulnerability in PHP by The PHP Group
CVE-2004-1019

Currently unrated

Key Information:

Vendor

PHP

Vendor
CVE Published:
10 January 2005

What is CVE-2004-1019?

The deserialization process in versions of PHP prior to 4.3.10 and 5.x up to 5.0.2 contains a vulnerability that allows remote attackers to send specially crafted data to the unserialize function. This can lead to a denial of service, execution of arbitrary code, and potential information disclosure. The flaw can trigger conditions such as double-free errors and underflow in negative reference index arrays, posing significant security risks to applications utilizing these PHP versions.

References

EPSS Score

7% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.